🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dcdffd85c4610e6701a6e6d06649066dee7671026d4ea8578da7d26cb2439b64. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 18


Intelligence 18 IOCs YARA 3 File information Comments

SHA256 hash: dcdffd85c4610e6701a6e6d06649066dee7671026d4ea8578da7d26cb2439b64
SHA3-384 hash: d0828001d3f65d60d95901d71c72b7c89347cbf84cd5f5522bd1d8f4996652d97b6344a6fd3f80f26c00bdaf7d27e3e7
SHA1 hash: 60c9c8eee0c3a6a7e06e24efabce4328f3a5e920
MD5 hash: 6b2f3efcd3d414752a53aa1d0386b62d
humanhash: quiet-stream-earth-nevada
File name:0009283Invoice0704202611022.exe
Download: download sample
Signature GuLoader
File size:456'040 bytes
First seen:2026-04-07 12:07:01 UTC
Last seen:2026-05-08 12:38:09 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 1f23f452093b5c1ff091a2f9fb4fa3e9 (303 x GuLoader, 47 x AgentTesla, 47 x RemcosRAT)
ssdeep 6144:XR+xXQQwnYELpYJ7HAXy0ds6xHGyMI0Y2ofGcJHEp1Cpvv8R:BswnbL+J7HFCx0I0Y3GcJkOmR
TLSH T171A4AD437D44F736CB9202F06A2DAC911672BDB1786FA5CEE3C13ADB96B1E8114392C1
TrID 50.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
10.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
10.5% (.EXE) Win64 Executable (generic) (6522/11/2)
8.1% (.EXE) Win16 NE executable (generic) (5038/12/1)
7.2% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon 9c74f8f8e4f0e102 (4 x AgentTesla, 2 x GuLoader)
Reporter James_inthe_box
Tags:exe GuLoader signed

Code Signing Certificate

Organisation:Heterosexually
Issuer:Heterosexually
Algorithm:sha256WithRSAEncryption
Valid from:2026-02-28T06:03:21Z
Valid to:2027-02-28T06:03:21Z
Serial number: 254eb1d285cd417c0faf081272df7c08bcdf32a9
Thumbprint Algorithm:SHA256
Thumbprint: e0a97c597c3db08fd9516aafc89644eb815e92a7679db5c130033d621cb381c8
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
2
# of downloads :
189
Origin country :
US US
Vendor Threat Intelligence
Gathering data
Malware family:
agenttesla
ID:
1
File name:
0009283Invoice0704202611022.exe
Verdict:
Malicious activity
Analysis date:
2026-04-07 12:07:32 UTC
Tags:
stealer ultravnc rmm-tool evasion agenttesla

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
92.5%
Tags:
injection obfusc virus
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% directory
Creating a window
Creating a file in the %AppData% subdirectories
Creating a file
Restart of the analyzed sample
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
adaptive-context anti-debug blackhole fingerprint installer installer installer-heuristic masquerade microsoft_visual_cc nsis signed soft-404
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-04-06T20:40:00Z UTC
Last seen:
2026-04-09T09:48:00Z UTC
Hits:
~1000
Detections:
Packed.NSIS.Krynis.sb VHO:Backdoor.Win32.Androm.gen Trojan.Win32.GuLoader.sb Trojan-PSW.Win32.Stealer.sb Trojan.NSIS.Pakes.Krynis.sb PDM:Trojan.Win32.Generic HEUR:Trojan-Downloader.Win32.Minix.gen Backdoor.Androm.HTTP.Download Trojan.NSIS.Makoob.sba Trojan-Downloader.Win32.Minix.sb
Gathering data
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2026-04-07 03:11:03 UTC
File Type:
PE (Exe)
Extracted files:
9
AV detection:
13 of 38 (34.21%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
cloudeye
Similar samples:
Result
Malware family:
guloader
Score:
  10/10
Tags:
family:agenttesla family:guloader discovery downloader keylogger spyware stealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Suspicious use of NtCreateThreadExHideFromDebugger
Suspicious use of NtSetInformationThreadHideFromDebugger
Looks up external IP address via web service
Loads dropped DLL
Reads WinSCP keys stored on the system
Reads data files stored by FTP clients
Reads user/profile data of local email clients
Reads user/profile data of web browsers
AgentTesla
Agenttesla family
Guloader family
Guloader,Cloudeye
Unpacked files
SH256 hash:
dcdffd85c4610e6701a6e6d06649066dee7671026d4ea8578da7d26cb2439b64
MD5 hash:
6b2f3efcd3d414752a53aa1d0386b62d
SHA1 hash:
60c9c8eee0c3a6a7e06e24efabce4328f3a5e920
SH256 hash:
3eb38ae99653a7dbc724132ee240f6e5c4af4bfe7c01d31d23faf373f9f2eaca
MD5 hash:
0d7ad4f45dc6f5aa87f606d0331c6901
SHA1 hash:
48df0911f0484cbe2a8cdd5362140b63c41ee457
SH256 hash:
1e40211af65923c2f4fd02ce021458a7745d28e2f383835e3015e96575632172
MD5 hash:
466179e1c8ee8a1ff5e4427dbb6c4a01
SHA1 hash:
eb607467009074278e4bd50c7eab400e95ae48f7
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Detect_NSIS_Nullsoft_Installer
Author:Obscurity Labs LLC
Description:Detects NSIS installers by .ndata section + NSIS header string
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments